OTL Extras logfile created on: 2/15/2014 6:28:33 AM - Run 1 OTL by OldTimer - Version 3.2.69.0 Folder = C:\Users\Rich\Downloads 64bit- Home Premium Edition Service Pack 1 (Version = 6.1.7601) - Type = NTWorkstation Internet Explorer (Version = 9.11.9600.16518) Locale: 00000409 | Country: United States | Language: ENU | Date Format: M/d/yyyy 3.91 Gb Total Physical Memory | 2.26 Gb Available Physical Memory | 57.75% Memory free 7.82 Gb Paging File | 6.07 Gb Available in Paging File | 77.68% Paging File free Paging file location(s): ?:\pagefile.sys [binary data] %SystemDrive% = C: | %SystemRoot% = C:\Windows | %ProgramFiles% = C:\Program Files (x86) Drive C: | 681.84 Gb Total Space | 637.40 Gb Free Space | 93.48% Space Free | Partition Type: NTFS Drive D: | 16.69 Gb Total Space | 2.05 Gb Free Space | 12.30% Space Free | Partition Type: NTFS Drive E: | 7.04 Mb Total Space | 0.00 Mb Free Space | 0.00% Space Free | Partition Type: CDFS Computer Name: RICH-HP | User Name: Rich | Logged in as Administrator. Boot Mode: Normal | Scan Mode: All users | Include 64bit Scans Company Name Whitelist: Off | Skip Microsoft Files: Off | No Company Name Whitelist: On | File Age = 30 Days [color=#E56717]========== Extra Registry (SafeList) ==========[/color] [color=#E56717]========== File Associations ==========[/color] [b]64bit:[/b] [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\] .html[@ = htmlfile] -- C:\Program Files\Internet Explorer\iexplore.exe (Microsoft Corporation) .url[@ = InternetShortcut] -- C:\Windows\SysNative\rundll32.exe (Microsoft Corporation) [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\] .cpl [@ = cplfile] -- C:\Windows\SysWow64\control.exe (Microsoft Corporation) .html [@ = htmlfile] -- C:\Program Files\Internet Explorer\iexplore.exe (Microsoft Corporation) [HKEY_USERS\S-1-5-21-4075957569-1680572243-469715140-1001\SOFTWARE\Classes\] .html [@ = FirefoxHTML] -- C:\Program Files (x86)\Mozilla Firefox\firefox.exe (Mozilla Corporation) [color=#E56717]========== Shell Spawning ==========[/color] [b]64bit:[/b] [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\\shell\[command]\command] batfile [open] -- "%1" %* cmdfile [open] -- "%1" %* comfile [open] -- "%1" %* exefile [open] -- "%1" %* helpfile [open] -- Reg Error: Key error. htmlfile [edit] -- Reg Error: Key error. htmlfile [open] -- "C:\Program Files\Internet Explorer\iexplore.exe" %1 (Microsoft Corporation) htmlfile [opennew] -- "C:\Program Files\Internet Explorer\iexplore.exe" %1 (Microsoft Corporation) htmlfile [print] -- "%systemroot%\system32\rundll32.exe" "%systemroot%\system32\mshtml.dll",PrintHTML "%1" http [open] -- "C:\Program Files\Internet Explorer\iexplore.exe" %1 (Microsoft Corporation) https [open] -- "C:\Program Files\Internet Explorer\iexplore.exe" %1 (Microsoft Corporation) inffile [install] -- %SystemRoot%\System32\InfDefaultInstall.exe "%1" (Microsoft Corporation) InternetShortcut [open] -- "C:\Windows\System32\rundll32.exe" "C:\Windows\System32\ieframe.dll",OpenURL %l (Microsoft Corporation) InternetShortcut [print] -- "C:\Windows\System32\rundll32.exe" "C:\Windows\System32\mshtml.dll",PrintHTML "%1" (Microsoft Corporation) piffile [open] -- "%1" %* regfile [merge] -- Reg Error: Key error. scrfile [config] -- "%1" scrfile [install] -- rundll32.exe desk.cpl,InstallScreenSaver %l scrfile [open] -- "%1" /S txtfile [edit] -- Reg Error: Key error. Unknown [openas] -- C:\Program Files\Hewlett-Packard\HP Application Assistant\HPAA.exe %1 (Hewlett Packard Company) Directory [cmd] -- cmd.exe /s /k pushd "%V" (Microsoft Corporation) Directory [find] -- %SystemRoot%\Explorer.exe (Microsoft Corporation) Folder [open] -- %SystemRoot%\Explorer.exe (Microsoft Corporation) Folder [explore] -- Reg Error: Value error. Drive [find] -- %SystemRoot%\Explorer.exe (Microsoft Corporation) Applications\iexplore.exe [open] -- "C:\Program Files\Internet Explorer\iexplore.exe" %1 (Microsoft Corporation) CLSID\{871C5380-42A0-1069-A2EA-08002B30309D} [OpenHomePage] -- "C:\Program Files\Internet Explorer\iexplore.exe" (Microsoft Corporation) [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\\shell\[command]\command] batfile [open] -- "%1" %* cmdfile [open] -- "%1" %* comfile [open] -- "%1" %* cplfile [cplopen] -- %SystemRoot%\System32\control.exe "%1",%* (Microsoft Corporation) exefile [open] -- "%1" %* helpfile [open] -- Reg Error: Key error. htmlfile [edit] -- Reg Error: Key error. htmlfile [open] -- "C:\Program Files\Internet Explorer\iexplore.exe" %1 (Microsoft Corporation) htmlfile [opennew] -- "C:\Program Files\Internet Explorer\iexplore.exe" %1 (Microsoft Corporation) htmlfile [print] -- "%systemroot%\system32\rundll32.exe" "%systemroot%\system32\mshtml.dll",PrintHTML "%1" http [open] -- "C:\Program Files\Internet Explorer\iexplore.exe" %1 (Microsoft Corporation) https [open] -- "C:\Program Files\Internet Explorer\iexplore.exe" %1 (Microsoft Corporation) inffile [install] -- %SystemRoot%\System32\InfDefaultInstall.exe "%1" (Microsoft Corporation) piffile [open] -- "%1" %* regfile [merge] -- Reg Error: Key error. scrfile [config] -- "%1" scrfile [install] -- rundll32.exe desk.cpl,InstallScreenSaver %l scrfile [open] -- "%1" /S txtfile [edit] -- Reg Error: Key error. Unknown [openas] -- C:\Program Files\Hewlett-Packard\HP Application Assistant\HPAA.exe %1 (Hewlett Packard Company) Directory [cmd] -- cmd.exe /s /k pushd "%V" (Microsoft Corporation) Directory [find] -- %SystemRoot%\Explorer.exe (Microsoft Corporation) Folder [open] -- %SystemRoot%\Explorer.exe (Microsoft Corporation) Folder [explore] -- Reg Error: Value error. Drive [find] -- %SystemRoot%\Explorer.exe (Microsoft Corporation) Applications\iexplore.exe [open] -- "C:\Program Files\Internet Explorer\iexplore.exe" %1 (Microsoft Corporation) CLSID\{871C5380-42A0-1069-A2EA-08002B30309D} [OpenHomePage] -- Reg Error: Value error. [color=#E56717]========== Security Center Settings ==========[/color] [b]64bit:[/b] [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center] "cval" = 1 [b]64bit:[/b] [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring] [b]64bit:[/b] [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Svc] "VistaSp1" = 28 4D B2 76 41 04 CA 01 [binary data] "AntiVirusOverride" = 0 "AntiSpywareOverride" = 0 "FirewallOverride" = 0 [b]64bit:[/b] [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Svc\Vol] [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center] [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Svc] [color=#E56717]========== Firewall Settings ==========[/color] [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\DomainProfile] "EnableFirewall" = 1 "DisableNotifications" = 0 [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\StandardProfile] "EnableFirewall" = 1 "DisableNotifications" = 0 [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\PublicProfile] "EnableFirewall" = 1 "DisableNotifications" = 0 [color=#E56717]========== Authorized Applications List ==========[/color] [color=#E56717]========== Vista Active Open Ports Exception List ==========[/color] [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\FirewallRules] "{1D43693C-1535-4C53-9970-CDD85C201246}" = lport=2177 | protocol=6 | dir=in | svc=qwave | app=%systemroot%\system32\svchost.exe | "{3B106484-13B1-4964-8F93-F10CD055972F}" = lport=138 | protocol=17 | dir=in | app=system | "{3FF9A45F-6D90-4081-9F1C-C079C3915732}" = lport=2177 | protocol=17 | dir=in | svc=qwave | app=%systemroot%\system32\svchost.exe | "{447A2954-6388-43C2-81E5-A001F6507414}" = lport=137 | protocol=17 | dir=in | app=system | "{4522AED6-2776-4072-87F4-3400364AD4F5}" = lport=445 | protocol=6 | dir=in | app=system | "{45A76500-B0CE-4937-9346-B4B3E83914AB}" = lport=5355 | protocol=17 | dir=in | svc=dnscache | app=%systemroot%\system32\svchost.exe | "{464AFD9C-6C9D-4144-8114-07EA0856CC01}" = rport=2177 | protocol=6 | dir=out | svc=qwave | app=%systemroot%\system32\svchost.exe | "{4FFCB3CA-6DBF-4316-BE31-D5A497ACE7A3}" = lport=1900 | protocol=17 | dir=in | name=windows live communications platform (ssdp) | "{507085CC-8CB7-4257-87CF-D96BCD119810}" = lport=1900 | protocol=17 | dir=in | svc=ssdpsrv | app=%systemroot%\system32\svchost.exe | "{5D7807D4-BA0C-4339-8C10-0CC0EB911F5C}" = rport=445 | protocol=6 | dir=out | app=system | "{676B750E-1DC1-46AC-8154-42E51B2E9CA2}" = rport=5355 | protocol=17 | dir=out | svc=dnscache | app=%systemroot%\system32\svchost.exe | "{7BB2EF25-B885-4617-8A39-524D747970A9}" = rport=2177 | protocol=17 | dir=out | svc=qwave | app=%systemroot%\system32\svchost.exe | "{8E222D0A-82B9-49C1-915C-FC4E7BD428BB}" = lport=2869 | protocol=6 | dir=in | app=system | "{948794FE-E5F8-4D99-A48C-55C275C3F25F}" = lport=rpc-epmap | protocol=6 | dir=in | svc=rpcss | name=@firewallapi.dll,-28539 | "{A02E023C-8079-4FA7-BEC2-921E3E43267F}" = rport=138 | protocol=17 | dir=out | app=system | "{A179F969-65F8-4445-BDDC-7AFA1962CE7A}" = rport=10243 | protocol=6 | dir=out | app=system | "{BE1B8266-5BB7-4C9B-8C1E-387D61357C20}" = rport=137 | protocol=17 | dir=out | app=system | "{C84448B3-909E-4846-90D9-514F5F035039}" = rport=1900 | protocol=17 | dir=out | svc=ssdpsrv | app=%systemroot%\system32\svchost.exe | "{D14B0EF4-3C10-40F6-BC53-F79283FAE440}" = lport=rpc | protocol=6 | dir=in | svc=spooler | app=%systemroot%\system32\spoolsv.exe | "{D30D4763-1DC0-49C2-BD1D-5806D4F9BB95}" = lport=2869 | protocol=6 | dir=in | name=windows live communications platform (upnp) | "{E3B1A843-726F-4F97-B36F-91FCAE77C98C}" = lport=10243 | protocol=6 | dir=in | app=system | "{EA3CD470-A613-4B33-8AB9-E690FF860A86}" = rport=139 | protocol=6 | dir=out | app=system | "{ED222235-A891-41E1-8DB4-0528972CBAEB}" = lport=139 | protocol=6 | dir=in | app=system | [color=#E56717]========== Vista Active Application Exception List ==========[/color] [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\FirewallRules] "{01E4EC0E-17A3-49D4-9491-B5DEA2E352D3}" = protocol=1 | dir=out | name=@firewallapi.dll,-28544 | "{0E00E30A-4F96-48BB-BBFF-64E5A85170F5}" = protocol=6 | dir=out | app=%programfiles%\windows media player\wmplayer.exe | "{1D5ED9B6-F274-45AF-A028-69909EA75B0B}" = protocol=58 | dir=out | name=@firewallapi.dll,-28546 | "{1FCBB2E6-86A5-479C-8B58-E42C129B71D9}" = protocol=6 | dir=out | app=c:\program files (x86)\hewlett-packard\remote graphics receiver\rgreceiver.exe | "{387CD476-BBFA-4BA6-A34B-53F68C55C38B}" = protocol=17 | dir=out | app=%programfiles(x86)%\windows media player\wmplayer.exe | "{4A3EAACF-E590-479C-9A12-3510DCA16D8A}" = protocol=6 | dir=out | app=%programfiles%\windows media player\wmpnetwk.exe | "{4BBCBFEB-802D-46F5-8E7B-E1FAC888CFD7}" = protocol=17 | dir=in | app=%programfiles(x86)%\windows media player\wmplayer.exe | "{5B0D94AF-2FBF-45B2-8DC4-3067EE9560AC}" = protocol=17 | dir=in | app=c:\program files (x86)\hewlett-packard\touchsmart\roxionow\rnow.exe | "{66201186-A939-4800-BEA0-FD7C72DF35DB}" = dir=in | app=c:\program files (x86)\windows live\mesh\moe.exe | "{70C3ABC9-2B60-468B-B738-F70B10AAA73F}" = dir=in | app=c:\program files (x86)\hewlett-packard\hp support framework\resources\hpwarrantycheck\hpdevicedetection3.exe | "{75974231-8D7D-4B89-A0AA-31D48DAF9AF9}" = protocol=17 | dir=in | app=c:\program files (x86)\hewlett-packard\hp linkup\hp linkup viewer.exe | "{779A1D5B-771C-4E0A-8AE3-E1EA99343825}" = protocol=17 | dir=in | app=c:\program files (x86)\hewlett-packard\touchsmart\roxionow\indivdrm.exe | "{84A8CEFD-851C-482E-B689-614E271E9707}" = protocol=6 | dir=out | app=%programfiles%\windows media player\wmplayer.exe | "{93DA27B6-0EF9-4125-A1B4-F1BE492A61CE}" = protocol=17 | dir=out | app=%programfiles%\windows media player\wmplayer.exe | "{98BFFDEC-AEEB-496C-8FB9-0A78E0C0D4CE}" = protocol=17 | dir=in | app=%programfiles%\windows media player\wmpnetwk.exe | "{99BE2629-FAF1-4AFC-9512-DEC97EFCB082}" = protocol=17 | dir=out | app=c:\program files (x86)\hewlett-packard\hp linkup\hp linkup viewer.exe | "{9D4CC687-157F-4543-BBDA-DA2E118E91D2}" = protocol=17 | dir=out | app=%programfiles%\windows media player\wmpnetwk.exe | "{9F8B5FB5-ECC1-42BD-A810-B00DE3DDC00D}" = protocol=58 | dir=in | name=@firewallapi.dll,-28545 | "{A345000E-88FA-4AA8-B86E-48161FF227A0}" = protocol=1 | dir=in | name=@firewallapi.dll,-28543 | "{B222FE30-5C7B-4FE1-BAED-0154F84165FA}" = protocol=6 | dir=in | app=%programfiles%\windows media player\wmpnetwk.exe | "{B95F4EC8-1947-452B-9F7B-FD5693A5B621}" = protocol=6 | dir=in | app=c:\program files (x86)\hewlett-packard\touchsmart\roxionow\indivdrm.exe | "{BC5A71B0-02A2-4518-A48E-0DBC5BBC1316}" = protocol=6 | dir=out | app=%programfiles(x86)%\windows media player\wmplayer.exe | "{CC021908-8533-457A-9549-B79E7A73EE84}" = protocol=17 | dir=in | app=%programfiles%\windows media player\wmplayer.exe | "{D4D91E78-974B-4F81-8E56-261F040871EF}" = dir=in | app=c:\program files (x86)\skype\phone\skype.exe | "{D87B5CEB-48CC-49C9-AED4-F297E739A23B}" = protocol=17 | dir=in | app=%programfiles%\windows media player\wmplayer.exe | "{DA036978-C4C3-4953-A2A2-AF6B23007BB9}" = protocol=6 | dir=out | svc=upnphost | app=%systemroot%\system32\svchost.exe | "{DBA4AB0D-A725-4982-9757-ED0AA4DCA65D}" = dir=in | app=c:\program files (x86)\windows live\messenger\msnmsgr.exe | "{DBE4CEA4-230F-433B-BD28-72879A2D7114}" = protocol=6 | dir=in | app=c:\program files (x86)\hewlett-packard\remote graphics receiver\rgreceiver.exe | "{E1BE9869-3900-4274-A4B9-CFD78E1058AD}" = protocol=6 | dir=out | app=system | "{E52AE715-7E23-4580-9B36-B628A51C7788}" = dir=in | app=c:\program files (x86)\windows live\contacts\wlcomm.exe | "{E5682766-0816-49DA-97EC-9EFF6420138B}" = protocol=17 | dir=out | app=%programfiles%\windows media player\wmplayer.exe | "{F663084A-2112-4833-91DE-B0D1E1F90F30}" = protocol=6 | dir=in | app=c:\program files (x86)\hewlett-packard\touchsmart\roxionow\rnow.exe | [color=#E56717]========== HKEY_LOCAL_MACHINE Uninstall List ==========[/color] 64bit: [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall] "{071c9b48-7c32-4621-a0ac-3f809523288f}" = Microsoft Visual C++ 2005 Redistributable (x64) "{180C8888-50F1-426B-A9DC-AB83A1989C65}" = Windows Live Language Selector "{1ACC8FFB-9D84-4C05-A4DE-D28A9BC91698}" = Windows Live ID Sign-in Assistant "{1D8E6291-B0D5-35EC-8441-6616F567A0F7}" = Microsoft Visual C++ 2010 x64 Redistributable - 10.0.40219 "{2856A1C2-70C5-4EC3-AFF7-E5B51E5530A2}" = HP Client Services "{421976B6-DEC6-4CA5-941F-F0663B3A2B74}" = Adobe Flash Player 11 ActiveX (x64) "{4B6C7001-C7D6-3710-913E-5BC23FCE91E6}" = Microsoft Visual C++ 2008 Redistributable - x64 9.0.30729.4148 "{656DEEDE-F6AC-47CA-A568-A1B4E34B5760}" = Windows Live Remote Service Resources "{6ce5bae9-d3ca-4b99-891a-1dc6c118a5fc}" = Microsoft Visual C++ 2005 Redistributable (x64) "{7DEBE4EB-6B40-3766-BB35-5CBBC385DA37}" = Microsoft .NET Framework 4.5.1 "{813BA625-B0FA-48D8-9B75-59759C88C219}" = SavingsbullFilter "{8220EEFE-38CD-377E-8595-13398D740ACE}" = Microsoft Visual C++ 2008 Redistributable - x64 9.0.30729.17 "{84481A87-2316-4923-8FAB-3BA8CA29323D}" = WinPatrol "{847B0532-55E3-4AAF-8D7B-E3A1A7CD17E5}" = Windows Live Remote Client Resources "{92FB6C44-E685-45AD-9B20-CADF4CABA132} - 1033" = Microsoft .NET Framework 4.5.1 "{95120000-00B9-0409-1000-0000000FF1CE}" = Microsoft Application Error Reporting "{B34A07DD-C6F7-414A-AE63-01019482EAF0}" = HP Application Assistant "{B47797F6-4C28-3F32-83DC-2784335CA487}" = Microsoft Visual Studio 2010 Tools for Office Runtime (x64) "{BCA9334F-B6C9-4F65-9A73-AC5A329A4D04}" = PlayReady PC Runtime amd64 "{CC4D56B7-6F18-470B-8734-ABCD75BCF4F1}" = HP Auto "{D79A02E9-6713-4335-9668-AAC7474C0C0E}" = HP Vision Hardware Diagnostics "{DA54F80E-261C-41A2-A855-549A144F2F59}" = Windows Live MIME IFilter "{DF6D988A-EEA0-4277-AAB8-158E086E439B}" = Windows Live Remote Client "{E02A6548-6FDE-40E2-8ED9-119D7D7E641F}" = Windows Live Remote Service "CCleaner" = CCleaner "Microsoft Visual Studio 2010 Tools for Office Runtime (x64)" = Microsoft Visual Studio 2010 Tools for Office Runtime (x64) [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall] "{07FA4960-B038-49EB-891B-9F95930AA544}" = HP Customer Experience Enhancements "{0B0F231F-CE6A-483D-AA23-77B364F75917}" = Windows Live Installer "{0EEC4E49-D4C2-4E23-87F2-B5641F1A09E4}" = HP Clock "{120262A6-7A4B-4889-AE85-F5E5688D3683}" = HP MovieStore "{16FC3056-90C0-4757-8A68-64D8DA846ADA}" = Remote Graphics Receiver "{19BA08F7-C728-469C-8A35-BFBD3633BE08}" = Windows Live Movie Maker "{1F1C2DFC-2D24-3E06-BCB8-725134ADF989}" = Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.4148 "{1F6AB0E7-8CDD-4B93-8A23-AA9EB2FEFCE4}" = Junk Mail filter update "{200FEC62-3C34-4D60-9CE8-EC372E01C08F}" = Windows Live SOXE Definitions "{20714B53-FC73-4F9C-9687-49EB237D6FD7}" = HP TouchSmart RecipeBox "{2902F983-B4C1-44BA-B85D-5C6D52E2C441}" = Windows Live Mesh ActiveX Control for Remote Connections "{2A3FC24C-6EC0-4519-A52B-FDA4EA9B2D24}" = Windows Live Messenger "{2B38E0FA-D8A5-4EBF-A018-E3C1C8E7A2E2}" = HP Calendar "{2EFA4E4C-7B5F-48F7-A1C0-1AA882B7A9C3}" = HP Update "{2FA94A64-C84E-49d1-97DD-7BF06C7BBFB2}.WildTangent Games App" = Update Installer for WildTangent Games App "{3336F667-9049-4D46-98B6-4C743EEBC5B1}" = Windows Live Photo Gallery "{34F4D9A4-42C2-4348-BEF4-E553C84549E7}" = Windows Live Photo Gallery "{3677D4D8-E5E0-49FC-B86E-06541CF00BBE}" = opensource "{3D171340-B528-42E0-92E4-BDA7AEEF6F32}_is1" = Spot "{3E29EE6C-963A-4aae-86C1-DC237C4A49FC}" = Intel(R) Rapid Storage Technology "{40A66DF6-22D3-44B5-A7D3-83B118A2C0DC}" = Norton Online Backup "{44B2A0AB-412E-4F8C-B058-D1E8AECCDFF5}" = Recovery Manager "{4D090F70-6F08-4B60-9357-A1DFD4458F09}" = Microsoft Mathematics "{579684A4-DDD5-4CA3-9EA8-7BE7D9593DB4}" = Windows Live UX Platform Language Pack "{5C5B24E7-4694-4049-A222-CCE7D3FAC63F}_is1" = CryptoPrevent v4.3.0 "{65153EA5-8B6E-43B6-857B-C6E4FC25798A}" = Intel(R) Management Engine Components "{682B3E4F-696A-42DE-A41C-4C07EA1678B4}" = Windows Live SOXE "{6F340107-F9AA-47C6-B54C-C3A19F11553F}" = Hewlett-Packard ACLM.NET v1.1.2.0 "{6F44AF95-3CDE-4513-AD3F-6D45F17BF324}" = HP Support Assistant "{70B446D1-E03B-4ab0-9B3C-0832142C9AA8}.WildTangent Games App-hp" = WildTangent Games App (HP Games) "{741006D1-7B2B-4E33-B2B0-831F282EEF64}" = Blio "{7E750542-55BC-4300-8B7B-AC2A762FB435}" = HP LinkUp "{8364E531-493B-4B05-8041-09D5CE38B975}" = HP Weather "{837b34e3-7c30-493c-8f6a-2b0f04e2912c}" = Microsoft Visual C++ 2005 Redistributable "{83C292B7-38A5-440B-A731-07070E81A64F}" = Windows Live PIMT Platform "{858FCB65-7C6D-4BA4-AD80-A3CB3744CE09}_is1" = HP Magic Canvas Tutorials "{86BAB08A-5E66-4C53-82E3-C1E91673C7CA}" = HP Notes "{89F4137D-6C26-4A84-BDB8-2E5A4BB71E00}" = Microsoft Silverlight "{8AE50893-3A87-4439-9A57-942ED43F7189}" = Facebook "{8C6D6116-B724-4810-8F2D-D047E6B7D68E}" = Mesh Runtime "{8DD46C6A-0056-4FEC-B70A-28BB16A1F11F}" = MSVCRT "{9008D736-35CA-40DB-A2BE-5F32D954E5AA}" = HP MovieStore "{912CED74-88D3-4C5B-ACB0-132318649765}" = PressReader "{92EA4134-10D1-418A-91E1-5A0453131A38}" = Windows Live Movie Maker "{95140000-0070-0000-0000-0000000FF1CE}" = Microsoft Office 2010 "{9A25302D-30C0-39D9-BD6F-21E6EC160475}" = Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.17 "{9D56775A-93F3-44A3-8092-840E3826DE30}" = Windows Live Mail "{A0C91188-C88F-4E86-93E6-CD7C9A266649}" = Windows Live Mesh "{A35E58D6-2A0F-4051-983B-79342081338E}" = HP RSS "{A726AE06-AAA3-43D1-87E3-70F510314F04}" = Windows Live Writer "{A9BDCA6B-3653-467B-AC83-94367DA3BFE3}" = Windows Live Photo Common "{AA59DDE4-B672-4621-A016-4C248204957A}" = Skype™ 5.5 "{AAAFC670-569B-4A2F-82B4-42945E0DE3EF}" = Windows Live Writer "{AAF454FC-82CA-4F29-AB31-6A109485E76E}" = Windows Live Writer "{AC76BA86-7AD7-1033-7B44-AB0000000001}" = Adobe Reader XI (11.0.06) "{AE856388-AFAD-4753-81DF-D96B19D0A17C}" = HP Setup Manager "{B2B7B1C8-7C8B-476C-BE2C-049731C55992}" = HP Support Information "{B8AC1A89-FFD1-4F97-8051-E505A160F562}" = HP Odometer "{B92C2C6C-F70E-497B-88A7-1FEF9888272B}" = Adobe AIR "{C01A86F5-56E7-101F-9BC9-E3F1025EB779}" = Intel(R) Identity Protection Technology 1.1.2.0 "{C66824E4-CBB3-4851-BB3F-E8CFD6350923}" = Windows Live Mail "{CCA5EAAD-92F4-4B7A-B5EE-14294C66AB61}" = PlayReady PC Runtime x86 "{CE95A79E-E4FC-4FFF-8A75-29F04B942FF2}" = Windows Live UX Platform "{D0661463-50F7-4A1E-83CB-37CC590589AE}_is1" = Metric Converter "{D0B44725-3666-492D-BEF6-587A14BD9BD9}" = MSVCRT_amd64 "{D436F577-1695-4D2F-8B44-AC76C99E0002}" = Windows Live Photo Common "{D45240D3-B6B3-4FF9-B243-54ECE3E10066}" = Windows Live Communications Platform "{DDC8BDEE-DCAC-404D-8257-3E8D4B782467}" = Windows Live Writer Resources "{DDFDC9D6-4220-41F8-BF9A-8E7512C4EF52}" = HP Magic Canvas "{DECDCB7C-58CC-4865-91AF-627F9798FE48}" = Windows Live Mesh "{E09C4DB7-630C-4F06-A631-8EA7239923AF}" = D3DX10 "{E3E71D07-CD27-46CB-8448-16D4FB29AA13}" = Microsoft WSE 3.0 Runtime "{E5B21F11-6933-4E0B-A25C-7963E3C07D11}" = Windows Live Messenger "{E8D46836-CD55-453C-A107-A59EC51CB8DC}" = VIP Access "{E9E34215-82EF-4909-BE2F-F581F0DC9062}" = DirectX for Managed Code Update (Summer 2004) "{F0B430D1-B6AA-473D-9B06-AA3DD01FD0B8}" = Microsoft SQL Server 2005 Compact Edition [ENU] "{F0C3E5D1-1ADE-321E-8167-68EF0DE699A5}" = Microsoft Visual C++ 2010 x86 Redistributable - 10.0.40219 "{F0E3AD40-2BBD-4360-9C76-B9AC9A5886EA}" = Intel(R) Processor Graphics "{F132AF7F-7BCA-4EDE-8A7C-958108FE7DBC}" = Realtek High Definition Audio Driver "{F5E7D9AF-60F6-4A30-87E3-4EA94D322CE1}" = HP Setup "{F89BADB0-D319-470E-8024-443EE3A3402B}" = TSHostedAppLauncher "{FE044230-9CA5-43F7-9B58-5AC5A28A1F33}" = Windows Live Essentials "38966_KeyCoupons" = KeyCoupons "Adobe AIR" = Adobe AIR "Adobe Flash Player Plugin" = Adobe Flash Player 12 Plugin "FileHippo.com" = FileHippo.com Update Checker "Malwarebytes' Anti-Malware_is1" = Malwarebytes Anti-Malware version 1.75.0.1300 "Mozilla Firefox 26.0 (x86 en-US)" = Mozilla Firefox 26.0 (x86 en-US) "MozillaMaintenanceService" = Mozilla Maintenance Service "NIS" = Norton Internet Security "PDF Complete" = PDF Complete Special Edition "Setup Support for Consumer Input" = Consumer Input "VIP Access SDK" = VIP Access SDK (1.0.1.4) "WildTangent hp Master Uninstall" = HP Games "WinLiveSuite" = Windows Live Essentials "WTA-0c0fb511-e1ae-4502-b146-04f7e0ae8d01" = Virtual Villagers 4 - The Tree of Life "WTA-0d3a1776-f461-43e1-a517-fc392355117e" = Final Drive Fury "WTA-14cf0fc0-944a-46d2-be84-96e601c261a2" = Polar Bowler "WTA-191ef8c0-c911-4313-a01a-5f47205df942" = Plants vs. Zombies - Game of the Year "WTA-227fb2c7-69ee-4127-9fab-1c248583190b" = Letters from Nowhere 2 "WTA-2f2fffa7-3a7f-4ddc-b465-bf86b095548a" = Farm Frenzy "WTA-300cc5ba-a7e1-4824-9304-5d5f6547aeae" = Polar Golfer "WTA-46e0c2ee-bdeb-45d5-9d3c-1d0c8ca16b00" = Poker Superstars III "WTA-46e140da-c8b8-4491-9f4b-c371fed7a37e" = Mah Jong Medley "WTA-4a05159e-6b6d-4bf6-876e-d5ec2fe36cda" = John Deere Drive Green "WTA-4cec465c-7b71-4ed0-9c51-9e3cdcadbec8" = Zuma's Revenge "WTA-58e1ce00-cb9d-4033-96d5-8d368ada7686" = Jewel Match 3 "WTA-61e8cba7-e309-495e-90fb-7526ff0bdc15" = The Treasures of Mystery Island: The Ghost Ship "WTA-631abed9-e1bc-4a35-8240-4b9c5f5eaf6f" = Torchlight "WTA-664f0ccd-2f07-485a-8188-e69d59e86b7b" = Blackhawk Striker 2 "WTA-6a6a1ca4-d409-4a02-9ffa-1648744e602e" = Chuzzle Deluxe "WTA-95c49cce-009c-4ab2-a066-2c8afef8c97a" = FATE "WTA-96f0d9ee-7c0b-4658-9b88-2431323693c0" = Cradle of Rome 2 "WTA-a22e15cd-b03a-41de-bce6-7f9f735ea7f8" = Bejeweled 3 "WTA-a853c508-a859-4ee9-903e-497c30755fcf" = Jewel Quest Mysteries: The Seventh Gate Collector's Edition "WTA-b2e1574c-fb55-4169-bc6d-09401cd6fb64" = Hoyle Card Games "WTA-b40c8b94-5f0d-47df-ad23-3604373c662f" = Dora's World Adventure "WTA-c140de1c-a1b1-4dcf-8bba-88d2fc7f72c9" = Luxor HD "WTA-c53895fe-60c3-4ec2-a0d2-75abcadda7ab" = RollerCoaster Tycoon 3: Platinum "WTA-cb99ab7e-cfde-4142-8d48-059e5709c112" = Farmscapes "WTA-f15ac199-4f24-4c8a-99db-dc39994260a1" = Penguins! [color=#E56717]========== HKEY_USERS Uninstall List ==========[/color] [HKEY_USERS\S-1-5-21-4075957569-1680572243-469715140-1001\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall] "DesktopWeatherAlerts" = DesktopWeatherAlerts [color=#E56717]========== Last 20 Event Log Errors ==========[/color] [ Application Events ] Error - 1/28/2014 9:15:18 PM | Computer Name = Rich-HP | Source = Windows Search Service | ID = 3029 Description = Error - 1/28/2014 9:15:19 PM | Computer Name = Rich-HP | Source = Windows Search Service | ID = 3029 Description = Error - 1/28/2014 9:15:19 PM | Computer Name = Rich-HP | Source = Windows Search Service | ID = 3028 Description = Error - 1/28/2014 9:15:19 PM | Computer Name = Rich-HP | Source = Windows Search Service | ID = 3058 Description = Error - 1/28/2014 9:15:19 PM | Computer Name = Rich-HP | Source = Windows Search Service | ID = 7010 Description = Error - 2/9/2014 8:34:47 PM | Computer Name = Rich-HP | Source = SavingsbullFilterService64 | ID = 7000 Description = Error - 2/9/2014 8:39:46 PM | Computer Name = Rich-HP | Source = Microsoft-Windows-CAPI2 | ID = 4101 Description = Failed auto update retrieval of third-party root certificate from: with error: This operation returned because the timeout period expired. . Error - 2/9/2014 8:39:48 PM | Computer Name = Rich-HP | Source = Microsoft-Windows-CAPI2 | ID = 4101 Description = Failed auto update retrieval of third-party root certificate from: with error: The specified server cannot perform the requested operation. . Error - 2/9/2014 8:39:48 PM | Computer Name = Rich-HP | Source = Microsoft-Windows-CAPI2 | ID = 4101 Description = Failed auto update retrieval of third-party root certificate from: with error: The specified server cannot perform the requested operation. . Error - 2/9/2014 8:39:48 PM | Computer Name = Rich-HP | Source = Microsoft-Windows-CAPI2 | ID = 4101 Description = Failed auto update retrieval of third-party root certificate from: with error: The specified server cannot perform the requested operation. . [ Hewlett-Packard Events ] Error - 1/19/2014 3:46:44 PM | Computer Name = Rich-HP | Source = HPSFMsgr.exe | ID = 4000 Description = HP Error ID: -2147221164 at System.RuntimeTypeHandle.CreateInstance(RuntimeType type, Boolean publicOnly, Boolean noCheck, Boolean& canBeCached, RuntimeMethodHandle& ctor, Boolean& bNeedSecurityCheck) at System.RuntimeType.CreateInstanceSlow(Boolean publicOnly, Boolean fillCache) at System.RuntimeType.CreateInstanceImpl(Boolean publicOnly, Boolean skipVisibilityChecks, Boolean fillCache) at System.Activator.CreateInstance(Type type, Boolean nonPublic) at HPSA_Messenger.MessengerCom.TrayDeskBand.isTaskbarDisplayed() StackTrace: at System.RuntimeTypeHandle.CreateInstance(RuntimeType type, Boolean publicOnly, Boolean noCheck, Boolean& canBeCached, RuntimeMethodHandle& ctor, Boolean& bNeedSecurityCheck) at System.RuntimeType.CreateInstanceSlow(Boolean publicOnly, Boolean fillCache) at System.RuntimeType.CreateInstanceImpl(Boolean publicOnly, Boolean skipVisibilityChecks, Boolean fillCache) at System.Activator.CreateInstance(Type type, Boolean nonPublic) at HPSA_Messenger.MessengerCom.TrayDeskBand.isTaskbarDisplayed() Source: mscorlib Name: HPSFMsgr.exe Version: 01.00.00.00 Path: C:\Program Files (x86)\Hewlett-Packard\HP Support Framework\Resources\HPSFMessenger\HPSFMsgr.exe Format: en-US RAM: 4002 Ram Utilization: 40 TargetSite: System.Object CreateInstance(System.RuntimeType, Boolean, Boolean, Boolean ByRef, System.RuntimeMethodHandle ByRef, Boolean ByRef) [ System Events ] Error - 1/20/2014 8:02:22 AM | Computer Name = Rich-HP | Source = Microsoft-Windows-WindowsUpdateClient | ID = 20 Description = Installation Failure: Windows failed to install the following update with error 0x80070643: Security Update for Microsoft XML Core Services 4.0 Service Pack 2 for x64-based Systems (KB954430). Error - 1/20/2014 8:12:21 AM | Computer Name = Rich-HP | Source = Microsoft-Windows-WindowsUpdateClient | ID = 20 Description = Installation Failure: Windows failed to install the following update with error 0x80070643: Update for Microsoft XML Core Services 4.0 Service Pack 2 for x64-based Systems (KB973688). Error - 1/20/2014 9:55:56 PM | Computer Name = Rich-HP | Source = Service Control Manager | ID = 7023 Description = The Windows Modules Installer service terminated with the following error: %%16405 Error - 1/20/2014 9:58:55 PM | Computer Name = Rich-HP | Source = Microsoft-Windows-WindowsUpdateClient | ID = 20 Description = Installation Failure: Windows failed to install the following update with error 0x80242016: Cumulative Security Update for Internet Explorer 9 for Windows 7 for x64-based Systems (KB2898785). Error - 1/21/2014 6:36:12 AM | Computer Name = Rich-HP | Source = NetBT | ID = 4321 Description = The name "WORKGROUP :1d" could not be registered on the interface with IP address 192.168.2.2. The computer with the IP address 192.168.2.1 did not allow the name to be claimed by this computer. Error - 1/21/2014 6:42:41 AM | Computer Name = Rich-HP | Source = Microsoft-Windows-WindowsUpdateClient | ID = 20 Description = Installation Failure: Windows failed to install the following update with error 0x80070103: Intel Corporation - Graphics Adapter WDDM1.1, Graphics Adapter WDDM1.2 - Intel(R) HD Graphics. Error - 1/28/2014 9:15:19 PM | Computer Name = Rich-HP | Source = Service Control Manager | ID = 7024 Description = The Windows Search service terminated with service-specific error %%-1073473535. Error - 1/28/2014 9:15:19 PM | Computer Name = Rich-HP | Source = Service Control Manager | ID = 7031 Description = The Windows Search service terminated unexpectedly. It has done this 1 time(s). The following corrective action will be taken in 30000 milliseconds: Restart the service. < End of report >